PW.1.1_pw11
Use forms of risk modeling – such as threat modeling, attack modeling, or attack surface mapping – to help assess the security risk for the software.
Browse reusable Agent Skills, each with a clear purpose and practical guidance.
Use forms of risk modeling – such as threat modeling, attack modeling, or attack surface mapping – to help assess the security risk for the software.
Where appropriate, build in support for using standardized security features and services (e.g., enabling software to integrate with existing log m...
Acquire and maintain well-secured software components (e.g., software libraries, modules, middleware, frameworks) from commercial, open-source, and ot
Verify that acquired commercial, open-source, and all other third-party software components comply with the requirements, as defined by the organizati
Determine whether executable code testing should be performed to find vulnerabilities not identified by previous reviews, analysis, or testing and, if
Define a secure baseline by determining how to configure each setting that has an effect on security or a security-related setting so that the default
Implement the default settings (or groups of default settings, if applicable), and document each setting for software administrators.
Establish and maintain a cyber threat hunting capability to: Search for indicators of compromise in organizational systems; and Detect, track, and dis
Conduct an impact-level prioritization of organizational systems to obtain additional granularity on system impact levels.
Categorize the system and information it processes, stores, and transmits;